Published: · Region: Global · Category: cyber

US seizes NightmareStresser DDoS‑for‑hire domains after hundreds of thousands of attacks

As part of Operation PowerOFF, US authorities have taken control of two domains tied to the NightmareStresser service, which investigators link to hundreds of thousands of distributed denial‑of‑service attacks worldwide since 2022.

US authorities have seized two internet domains linked to NightmareStresser, a DDoS‑for‑hire platform that investigators say has been used in hundreds of thousands of attacks and attempted attacks around the world since 2022.

The move is part of Operation PowerOFF, a broader campaign targeting services that sell distributed denial‑of‑service capability to paying customers. In a DDoS attack, an online service is flooded with traffic until it can no longer respond to legitimate users.

By taking over the domains, US agencies are trying to cut off access to a platform that allowed people with minimal technical knowledge to launch disruptive attacks against websites and small networks. While the operation doesn’t remove all such services from the internet, it interrupts one channel that has been active for several years.

For organizations that have suffered repeated outages—small businesses, schools, local government portals—each takedown narrows the pool of tools would‑be attackers can easily rent. But experience with similar cases suggests operators may attempt to resurface under new names or web addresses.

The key questions now are whether related infrastructure linked to NightmareStresser is also targeted, how quickly copycat or successor services appear, and whether Operation PowerOFF expands to include more platforms offering DDoS‑for‑hire.

Sources